Live data from Hacker News

Ask HN: Is the ISO 27001 certification worth it?

news.ycombinator.com

51–60 of 104 posts

Re: Ask HN: Is the ISO 27001 certification worth it?

#51
Let me put my perspective on this.

The answer is both yes, and no.

Why no:

Seriously, if you need certification to put your processes in order you are in a deep shit anyway. As an organization, you should be striving to continuously learn and improve. ISO 27001 is just a standard, a minimum you should be doing anyway.

Why yes:

I think it makes sense to go over that material. A lot of that stuff makes total sense. Why learn the mistakes yourself when you can get over a lot of that stuff in one, easy to consume package? Security is a tough thing to get right, there is a lot of possibility to forget/be blind to some obvious things. While it is up to you to figure out what to do (see above) and you will be paying the price of missteps, it is always good idea to get some external validation. Especially if you are top level manager and you don't exactly know if you are getting accurate assessment of the situation from your underlings.

Re: Ask HN: Is the ISO 27001 certification worth it?

#52
post #24
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

My experience doing this for several large companies at a time is that the questionnaires don't really go away with certification. There are probably some shops where audit reports will substitute for the Excel spreadsheet Q&A's, but there are plenty of others where the Q&A is a dealbreaker part of procurements no matter what. If you're in a line of business where your customers have questionnaires, just plan on havi…

Agreed with this, we still get questionnaires.

Re: Ask HN: Is the ISO 27001 certification worth it?

#53
post #3

I worked for a telecomms/webcasting company for about 5 years as a product manager. I can tell you from personal experience that a significant portion of the Fortune 500 (if not all of them) required ISO 2700X certification to even be considered. The certification burden increases in proportion to the level of PII you are storing. The burden was much higher for government or med/bio contracts (FedRAMP/HIPPA, etc.). I…

My experience is, you get to work with a company who "advices" you what to do and they also do the certification. In my opinion, this makes it worthless. The company i worked for got the certification like this every year.

Re: Ask HN: Is the ISO 27001 certification worth it?

#54
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

There's a very recently announced (https://security.googleblog.com/2021/10/launching-collaborat...) initiative by Google, Salesforce, Okta, Slack and others to create a minimal security standard - https://mvsp.dev/ - which will hopefully reduce this overhead and encourage an improvement in security across the industry.

Re: Ask HN: Is the ISO 27001 certification worth it?

#55

It's theatre, so it won't help actual security. Having said that, even quite small firms I've known have decided they needed it in order to get customers. A fair few large customers require it and won't bother talking to you if you don't have it, so if you can otherwise do the sale there's a good reason to get it. Your real problem as a small vendor is deciding when this is necessary, because you might be getting cus…

We are in the 'lucky' position that ISO 27001 is now simply a legal requirement because we offer a healthcare SaaS-product in the Netherlands (ISO 27001 is required via its Dutch NEN 7510/12/13 bastard child that is). For a small company (less than twenty employees) it really is a lot of work. It brings some benefits in that it forces you to have your documentation and certain processes in order, but man… getting aud…

We’re also certified for similar reasons. It did bring information security more in the focus of upper management, so that’s a plus. I for the time for backup encryption, getting rid of outdated servers (fuck Arch Linux, really), and everyone now has a monitored laptop, and got a info sec training.

Re: Ask HN: Is the ISO 27001 certification worth it?

#56
post #32

It's theatre, so it won't help actual security. Having said that, even quite small firms I've known have decided they needed it in order to get customers. A fair few large customers require it and won't bother talking to you if you don't have it, so if you can otherwise do the sale there's a good reason to get it. Your real problem as a small vendor is deciding when this is necessary, because you might be getting cus…

> It's theatre, so it won't help actual security. I disagree with this sentiment. As a small firm who has undergone multiple security audits/certifications, I have found that the controls we added were generally practical and did improve our security.

This is also my experience with risk audits in IT: you get asked a lot of stupid questions and spend a lot of time engaging in extreme hypotheticals, but in the end there are always one or two “hmmm I hadn’t thought of that” moments which lead you to significantly increase your security.

Re: Ask HN: Is the ISO 27001 certification worth it?

#57
post #24
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

My experience doing this for several large companies at a time is that the questionnaires don't really go away with certification. There are probably some shops where audit reports will substitute for the Excel spreadsheet Q&A's, but there are plenty of others where the Q&A is a dealbreaker part of procurements no matter what. If you're in a line of business where your customers have questionnaires, just plan on havi…

We got a SOC2... and still get questionnaires. It's the worst. Companies are just outsourcing their security reviews to the vendor. Rather than rely on a 3rd party audited document companies want their custom questions answered. BUT - they aren't custom questions - it's the same questions for every vendor and they are very often poorly worded. Then when we turn them in - there's no follow up questions which to me implies that no one is reading them. Security theater...

Re: Ask HN: Is the ISO 27001 certification worth it?

#58
post #12

> When did you decide that it's time to get it done? There is a time management component to this. If you're still in a deal without a 27001 certification, the security questions don't go away. Instead, you get sent a security question set to answer. These question sets can be huge - our record is about 300 - 400 questions. And once you've answered those, you're not done - then you go into discussions with their cybe…

There's a very recently announced ( https://security.googleblog.com/2021/10/launching-collaborat... ) initiative by Google, Salesforce, Okta, Slack and others to create a minimal security standard - https://mvsp.dev/ - which will hopefully reduce this overhead and encourage an improvement in security across the industry.

I note that section 1.6 is "Comply with all industry security standards relevant to your business such as PCI DSS, HITRUST, ISO27001, and SSAE 18".

That looks larger than all the other requirements.

Re: Ask HN: Is the ISO 27001 certification worth it?

#59

(I work at/cofounded Vanta) We work with companies doing B2B sales and looking for help with compliance certifications like ISO 27001 and SOC 2. Some folks come to us early but most come with a deal on the line — which is to say, this is a process you can start “just in time” if you must. From what I’ve seen, saying “no I won’t go through your security review process” is an (obvious) dealbreaker, but there’s a lot of…

How can one reach you at Vanta?

Re: Ask HN: Is the ISO 27001 certification worth it?

#60

Earlier quoted context omitted.

There's a very recently announced ( https://security.googleblog.com/2021/10/launching-collaborat... ) initiative by Google, Salesforce, Okta, Slack and others to create a minimal security standard - https://mvsp.dev/ - which will hopefully reduce this overhead and encourage an improvement in security across the industry.

I note that section 1.6 is "Comply with all industry security standards relevant to your business such as PCI DSS, HITRUST, ISO27001, and SSAE 18". That looks larger than all the other requirements.

Yes, unsurprisingly, this is set up to protect incumbents that have collected all these certifications.
Post reply on HN